Debian Security Advisory
DLA-78-1 torque -- LTS security update
- Date Reported:
- 27 Oct 2014
- Affected Packages:
- torque
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2014-3684.
- More information:
-
Chad Vizino reported a vulnerability in torque, a PBS-derived batch processing queueing system. A non-root user could exploit the flaw in the tm_adopt() library call to kill any process, including root-owned ones on any node in a job.
For Debian 6
Squeeze
, these issues have been fixed in torque version 2.4.8+dfsg-9squeeze5